CISM (Certified Information Security Manager)

ISACA

Complete guide to passing the CISM (Certified Information Security Manager) exam on your first attempt.

HardHigh Search Volume
Key Information at a Glance
Cost

$575-$760

Pass Rate

~50%

Validity

3 years

Region

Global

Provider

ISACA

Salary Impact

$120k-$170k

Are you ready for CISM (Certified Information Security Manager)?

Loading quiz...

Complete Overview

The Certified Information Security Manager (CISM) is a four-hour, 150-question multiple-choice certification exam from ISACA that costs US$575 for ISACA members and US$760 for non-members. It is written for people who manage, design, oversee, and assess an enterprise information security function rather than for engineers who configure the controls themselves.

Scores are reported on a scaled range of 200 to 800, and 450 is the passing mark. A score of 800 means every question was answered correctly, and 200 is the floor. The exam mixes scored items with unmarked pretest items that do not count toward your score, so treat every question as live. Scoring is based purely on the number of items answered correctly, with no penalty for wrong answers, so leaving a question blank only costs you. ISACA provides domain-level percentages on the score report for information only; they carry no separate pass requirement, and question-level results are never released.

Four job practice domains carry uneven weights, which surprises candidates who assume equal coverage. Information Security Program is by far the largest at 33 percent, Incident Management follows at 30 percent, Information Security Risk Management is 20 percent, and Information Security Governance is 17 percent. Between them, the program and incident domains account for 63 percent of the exam. ISACA has announced that the CISM Exam Content Outline will be updated effective 3 November 2026, with preparation material for the new outline going on sale in September 2026.

Exams are computer-based and delivered either at authorized PSI testing centers worldwide or as remotely proctored sessions. Registration is continuous with no exam windows, and you can schedule an appointment as early as 48 hours after paying in full. Eligibility lasts six months from registration, extendable once by six months for US$75. Exam tasks are offered in English, Spanish, Simplified Chinese, Japanese, French, and German.

Passing the exam is only step one. Certification also requires paying a US$50 application processing fee, submitting an application demonstrating five or more years of information security management work experience gained within the 10 years preceding the application, and agreeing to ISACA's Code of Professional Ethics and Continuing Professional Education policy. Experience waivers are available for a maximum of two years. You have five years from your passing date to apply.

Once certified, the credential is maintained rather than re-earned. You report a minimum of 20 CPE hours each year and at least 120 CPE hours across each three-year reporting period, and you pay an annual maintenance fee of US$45 for members or US$85 for non-members, due by 1 January each year. Failing to comply with a random CPE audit results in revocation.

Why Get CISM (Certified Information Security Manager) Certified?

CISM is the ISACA credential aimed squarely at security management rather than security engineering, and 63 percent of the exam covers running a security program and managing incidents.

ISACA reports that more than 48,000 professionals hold the CISM, and lists the credential as a requirement at many organizations and government agencies.

The certification application requires five years of experience across at least three of the four CISM domains, so holding it signals breadth across governance, risk, program, and incident work rather than depth in one corner of security.

ISACA membership pays for itself on the exam alone: the member fee is US$575 against US$760 for non-members, a US$185 difference, and members also pay US$45 rather than US$85 for the annual maintenance fee.

Maintenance is by continuing education, not by re-examination. Twenty CPE hours per year and 120 across three years keeps the credential current with no second sitting.

You can sit the exam before you meet the experience requirement. ISACA gives you five years from your passing date to submit the certification application, so the exam can be taken while you accumulate the required five years.

The exam maps directly onto frameworks CISOs already use, including business impact analysis, risk appetite, incident classification, and post-incident review, so preparation transfers into board-level reporting work.

Exam Format & Structure

Duration

4 hours (240 minutes)

Questions

150 questions

Passing Score

450 on a scaled range of 200 to 800

Question Types

  • Multiple choice, four options per question, one best answer
  • Scenario-based items that ask what a security manager should do first, next, or best

Delivery Method

Computer-based at authorized PSI testing centers globally, or remotely proctored through PSI

Exam Domains & Topics

Information security program
33%

The largest domain by a wide margin, split into program development and program management. Development covers program resources, asset identification and classification, industry standards and frameworks, policy and procedure hierarchies, and program metrics. Management covers control design and selection, implementation and integration, control testing and evaluation, awareness and training, third-party management, and reporting.

Key Topics to Master:

  • Information security program resources: people, tools, technologies
  • Information asset identification and classification
  • Industry standards and frameworks for information security
  • The hierarchy of policies, standards, procedures, and guidelines
  • Information security program metrics and how they differ from operational metrics
  • Security control design, selection, implementation, and integration
  • Control testing and evaluation methods
  • Security awareness and training program design
  • Management of external providers, suppliers, third parties, and fourth parties
Incident management
30%

Divided into readiness and operations. Readiness covers the incident response plan and its alignment with business continuity and disaster recovery plans, business impact analysis, incident classification, and testing. Operations covers tools and techniques, investigation and evaluation, containment methods, response communications including notification and escalation, eradication and recovery, and post-incident review.

Key Topics to Master:

  • Incident response plan development and its alignment with BCP and DRP
  • Business impact analysis and the derivation of RTO and RPO
  • Incident classification and categorization schemes
  • Incident management training, testing, tabletop exercises, and simulation
  • Incident investigation, evidence handling, and evaluation
  • Containment methods and the decision to contain versus observe
  • Incident response communications: reporting, notification, escalation
  • Eradication and recovery sequencing
  • Post-incident review, root cause analysis, and lessons learned
Information security risk management
20%

Covers risk assessment and risk response as two halves. Assessment deals with the emerging risk and threat landscape, vulnerability and control deficiency analysis, and risk assessment and analysis method. Response deals with treatment options, assigning risk and control ownership, and the monitoring and reporting cycle that keeps senior leadership informed.

Key Topics to Master:

  • Emerging risk and the evolving threat landscape
  • Vulnerability analysis and control deficiency analysis
  • Qualitative and quantitative risk assessment and analysis
  • Risk treatment options: mitigate, transfer, avoid, accept
  • Risk appetite and risk tolerance as decision boundaries
  • Risk and control ownership assignment
  • Risk monitoring and reporting to stakeholders
  • Integrating information risk management into business and IT processes
Information security governance
17%

The smallest domain, covering enterprise governance and information security strategy. Enterprise governance includes organizational culture, legal and regulatory and contractual requirements, and organizational structures with their roles and responsibilities. Strategy includes strategy development, information governance frameworks and standards, and strategic planning across budgets, resources, and business cases.

Key Topics to Master:

  • Organizational culture and its effect on security strategy
  • Legal, regulatory, and contractual requirements
  • Organizational structures, roles, and responsibilities
  • Information security strategy development aligned to business objectives
  • Information governance frameworks and standards
  • Strategic planning: budgets, resources, and business cases
  • Integrating information security governance into corporate governance
  • Gaining and keeping senior leadership commitment

Recommended Study Plan

Week 1: Blueprint, mindset, and registration
6-8 hours
  • 1Read the CISM Exam Content Outline on isaca.org and write out the four domain weights next to each other so the 33 and 30 percent split registers
  • 2Read all 37 supporting tasks in the content outline; they describe the exam's point of view more precisely than any study guide
  • 3Take ISACA's free 10-question CISM practice quiz to see how management-perspective items are worded
  • 4Register for the exam so your six-month eligibility window starts and creates a deadline
  • 5Confirm the name on your ISACA account matches your government-issued photo ID exactly
Week 2: Governance foundations
8-10 hours
  • 1Work through the governance chapter of the CISM Review Manual
  • 2Write a one-page information security strategy for a fictional company aligned to three stated business objectives
  • 3List the legal, regulatory, and contractual requirements that apply to your own employer and note who owns each
  • 4Map three governance frameworks against each other and note where responsibilities sit
  • 5Answer 60 questions from the governance domain in the CISM Questions, Answers and Explanations database
Week 3: Strategy, business cases, and stakeholder reporting
8-10 hours
  • 1Draft a business case for a security investment with cost, risk reduction, and residual risk stated explicitly
  • 2Practice distinguishing a security metric that a board cares about from one that only an operations team uses
  • 3Read the governance-related supporting tasks 1 through 10 and write which domain answer style each implies
  • 4Review every governance question you got wrong last week and write why the correct answer is more managerial than yours
  • 5Answer another 60 governance questions and target 75 percent accuracy
Week 4: Risk assessment
10-12 hours
  • 1Work through the risk management chapter of the CISM Review Manual
  • 2Build a risk register entry end to end: threat, vulnerability, likelihood, impact, inherent risk, control, residual risk
  • 3Compare a qualitative and a quantitative assessment of the same scenario and note when each is appropriate
  • 4Write definitions of risk appetite and risk tolerance in your own words and one example of each being exceeded
  • 5Answer 80 risk domain questions in the QAE database
Week 5: Risk response, ownership, and reporting
8-10 hours
  • 1Practice choosing between mitigate, transfer, avoid, and accept for ten scenarios where more than one is defensible
  • 2Write out who owns a risk versus who owns a control in three different organizational structures
  • 3Build a one-page risk report for senior leadership showing changes since last quarter
  • 4Study the difference between a control deficiency and a vulnerability as ISACA uses the terms
  • 5Review all missed risk questions and classify each error as knowledge, perspective, or misreading
Week 6: Security program development
10-12 hours
  • 1Work through the program development portion of the CISM Review Manual
  • 2Build an asset classification scheme with four tiers and a handling requirement for each
  • 3Write the policy, standard, procedure, and guideline for one control and keep the hierarchy strict
  • 4Define five program metrics and state the audience and decision each supports
  • 5Answer 80 program domain questions, the largest bank you will need for any single domain
Week 7: Security program management
10-12 hours
  • 1Study control design and selection versus control implementation and integration as separate decisions
  • 2Design a control testing and evaluation schedule and state what evidence each test produces
  • 3Outline an awareness and training program with different content for three audiences
  • 4Write third-party security requirements into a sample contract clause, then define how you would monitor adherence
  • 5Answer another 80 program questions and target 75 percent accuracy given the domain's 33 percent weight
Week 8: Incident management readiness
10-12 hours
  • 1Work through the incident management chapter of the CISM Review Manual
  • 2Write an incident response plan outline and show explicitly where it references the BCP and the DRP
  • 3Run a business impact analysis on one business process and derive RTO and RPO from it
  • 4Build an incident classification scheme with severity levels and escalation triggers for each
  • 5Design a tabletop exercise scenario and list the specific decisions it is meant to test
Week 9: Incident management operations
10-12 hours
  • 1Practice sequencing containment, eradication, and recovery for scenarios where the ordering is contested
  • 2Write a notification matrix showing who is told what, by whom, and within what regulatory deadline
  • 3Study when preserving evidence outweighs immediate containment and how a manager decides
  • 4Draft a post-incident review agenda covering root cause, lessons learned, corrective actions, and risk reassessment
  • 5Answer 80 incident management questions, matching the domain's 30 percent weight
Week 10: Full-length practice under time
10-12 hours
  • 1Sit a 150-question timed practice exam in one 240-minute block using the QAE database
  • 2Score by domain and compare your accuracy against the 17, 20, 33, and 30 percent weights to see where marks are actually at stake
  • 3Review every question you got wrong and every question you guessed correctly
  • 4For each error, write whether you chose a technically correct but managerially wrong answer
  • 5Reread the review manual sections behind your two weakest domains
Week 11: Answer discipline and weak areas
8-10 hours
  • 1Drill the four qualifier words that decide CISM answers: first, best, most, and primary
  • 2Work through 150 more questions in mixed-domain mode rather than by domain
  • 3Rewrite the definitions of the twenty terms you keep confusing, using ISACA's glossary wording
  • 4Practice pacing at 96 seconds per question so 150 questions fit inside 240 minutes with review time
  • 5Read the ISACA Certification Exam Candidate Guide sections on exam day rules and prohibited items
Week 12: Final rehearsal and logistics
8-10 hours
  • 1Sit a second full 150-question timed exam and treat any score gap from week 10 as your real remaining risk
  • 2If testing remotely, run the PSI device compatibility check on the exact machine and clear the room of all materials
  • 3If testing at a PSI center, confirm the address and plan to arrive early, since arriving more than 15 minutes late forfeits the appointment
  • 4Prepare a single current, valid, original government-issued ID with your name, photo, and signature on it
  • 5Read your notes on the four domains one final time, weighted toward the program and incident domains

Ready to pass CISM (Certified Information Security Manager)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$288$144

Best Study Resources

CISM Exam Content Outline

Official blueprint

ISACA's published outline with the four domain weights, every subtopic beneath them, and all 37 supporting tasks. Note the disclaimer: the outline is being updated effective 3 November 2026, so confirm which version applies to your test date.

Free

CISM Review Manual

Official study guide

ISACA's own reference covering all four domains and the information security management roles and responsibilities the exam assumes. Buying the correct edition matters because the content outline changes on 3 November 2026.

Paid; available in digital and print from ISACA, with member pricing

CISM Questions, Answers and Explanations Database

Practice question bank

A pool of 1,047 questions with a personalized dashboard, custom study plans, progress tracking, and review of previously answered items. This is the closest thing available to the real item style, which is where most preparation value sits for CISM.

Paid six-month subscription, with member pricing

CISM Online Review Course

Self-paced course

ISACA's own self-paced course covering key concepts from all four domains. Useful for candidates whose experience is concentrated in one or two domains and who need structured coverage of the rest.

Paid, from ISACA

Free CISM Practice Quiz

Sample questions

Ten free questions from ISACA testing information security management, cybersecurity, and risk. Ten questions will not measure readiness, but they will show you within minutes whether you are answering from a manager's chair or an engineer's.

Free

ISACA Certification Exam Candidate Guide

Official policy guide

Covers registration, eligibility, scheduling, exam day rules, prohibited items, break policy, scoring, and the retake policy for CISA, CISM, CGEIT, CRISC, and CDPSE. Available in English, Simplified Chinese, French, German, Japanese, Korean, and Spanish.

Free

Engage CISM study groups

Community forum

ISACA's member-only online forum acting as a global virtual study group for CISM candidates, with practice questions and answers from other members. One of the concrete returns on paying for membership alongside the reduced exam fee.

Free to ISACA members

ISACA CPE Policy document

Official policy

The rules that govern your credential after you earn it: the 20 hours annually and 120 hours per three-year cycle requirement, what activities qualify, recordkeeping standards, and what happens in a CPE audit.

Free

ISACA glossary and CISM terminology translations

Reference

ISACA's definitions are the ones the exam uses, and they sometimes differ from common industry usage. The terminology list is translated into Simplified Chinese, Japanese, and Spanish for candidates testing in those languages.

Free

ISACA Remote Proctoring Guide

Official procedure guide

Required reading if you plan to test from home. It covers the device compatibility check, the secure browser download, the room and desk requirements, the mirror check, and where your phone must be placed once check-in is complete.

Free

Common Mistakes to Avoid

Answering questions from a technical practitioner's point of view instead of a security manager's.

CISM items usually contain a technically correct option that is still wrong because the manager's next step is different. When two options both work, choose the one that involves the business, escalates appropriately, or aligns to strategy and risk appetite rather than the one that fixes the machine.

Studying all four domains equally because the CISM domain list looks symmetrical.

The weights are 17 percent governance, 20 percent risk management, 33 percent program, and 30 percent incident management. Program and incident management alone carry 63 percent of the exam. Allocate study hours to match, and treat governance as the domain to master rather than the one to over-invest in.

Ignoring the qualifier word in the stem and choosing the first defensible option.

CISM stems hinge on first, best, most, and primary. Best asks for the strongest option overall; first asks for sequence. Circle the qualifier before you look at the options, and when the qualifier is first, order the four options chronologically before choosing.

Assuming a passing score is 450 out of 800 and therefore about 56 percent of questions.

450 is a scaled score, not a raw count. ISACA converts your raw score to a common 200 to 800 scale so that different exam forms are comparable. There is no published raw-to-scaled conversion, so judge readiness by consistent accuracy on the official question bank rather than by reverse-engineering a percentage.

Leaving questions blank when time runs short.

ISACA states there is no penalty for incorrect answers and that grades are based solely on the total number of questions answered correctly. Every blank is a guaranteed zero. With 150 questions in 240 minutes, reserve the final five minutes to fill in anything unanswered.

Passing the exam and then letting the certification application lapse.

Passing does not make you certified. You must also pay the US$50 application processing fee, submit an application demonstrating five or more years of information security management experience gained within the preceding 10 years, and agree to the Code of Professional Ethics and CPE policy. You have five years from the passing date to do it.

Letting the six-month exam eligibility window expire without scheduling.

Eligibility is established at registration and lasts six months, and fees are nonrefundable and nontransferable. If you need more time, a six-month extension costs US$75, the option sits on your dashboard from 30 days before expiry until 30 days after, and you may extend only once. Book a date early, since appointments are only available 90 days in advance and you can reschedule free up to 48 hours ahead.

Preparing with material written for a different version of the exam content outline.

ISACA has announced that the CISM Exam Content Outline is updated effective 3 November 2026, with prep material for the new outline available from September 2026. ISACA also states that purchasing current material does not grant access to the newer material later. Check your test date against that cutover before you buy anything.

Confusing risk appetite with risk tolerance, or a control deficiency with a vulnerability.

CISM tests ISACA's definitions, not general industry usage. Risk appetite is the amount of risk an organization is willing to pursue; tolerance is the acceptable variation around it. Learn the terms from the ISACA glossary and the review manual rather than from vendor blogs, because distractors are built from the looser popular definitions.

Exam Day Tips

  • 1

    Bring one current, valid, original government-issued ID showing your name, photograph, and signature, and make sure all three appear on that single document. Copies, handwritten IDs, and digital IDs are refused, and a first and last name that do not match your registration can stop you entering and forfeit the fee.

  • 2

    Arriving more than 15 minutes late for your testing appointment costs you the appointment. For remote sessions, run the PSI device compatibility check well before test day, and if you are on a company machine, get IT approval for the secure browser download in advance.

  • 3

    Calculators are prohibited, as are reference materials, paper, notes, notepads, and language dictionaries. There is no calculation-heavy content on CISM, so nothing is lost by their absence.

  • 4

    Multiple monitors are prohibited. Disconnect the second screen before check-in rather than arguing with a proctor about it during the mirror check.

  • 5

    Food and beverages are banned during the exam, and ISACA states this includes water and applies to both on-site and remotely proctored sessions. Hydrate before you check in, not during.

  • 6

    Two breaks of no more than ten minutes each are permitted with your proctor's permission. The exam is paused during an approved break, but the timer does not stop, so a break costs you real exam minutes out of the 240.

  • 7

    You may not take screenshots or photographs of any part of the exam, including the results screen. Doing so voids the exam under ISACA's zero-tolerance policy.

  • 8

    For remote sessions, your phone must be placed out of reach of the testing room once the mirror check is complete, and no one else may enter or walk through the room for the full four hours.

  • 9

    You will see a preliminary pass or fail status on screen the moment you finish. Do not treat that as final and do not photograph it; the official score arrives by email and in MyISACA within 10 working days.

  • 10

    Pace at roughly 96 seconds per question. That gets all 150 answered inside 240 minutes and leaves time to return to flagged items and to fill in any blanks before you submit.

Career Paths & Salary Ranges

Information security manager

Runs the security program day to day: policy, control selection, awareness training, third-party oversight, and reporting upward. This role is the one the CISM job practice was written from, and the 33 percent program domain matches its responsibilities directly.

$120k-$170k

Chief information security officer

Owns strategy, budget, and the board conversation. The governance domain's strategic planning, business case, and senior leadership commitment topics are exactly the parts of the job that cannot be delegated.

$120k-$170k

IT risk manager

Runs risk identification, assessment, treatment selection, and reporting cycles. The 20 percent risk management domain covers the assessment methods and the risk and control ownership model this role operates.

$120k-$170k

Incident response manager

Owns readiness and coordination rather than forensic keyboard work: response plan maintenance, classification schemes, tabletop exercises, notification and escalation, and post-incident review. Incident Management is 30 percent of the exam.

$120k-$170k

Security governance and compliance lead

Keeps the program aligned to legal, regulatory, and contractual requirements and to the frameworks the enterprise has adopted. Draws on the governance domain and on the external party management topics inside the program domain.

$120k-$170k

Security consultant or virtual CISO

Advises multiple client organizations on program build-out and risk posture. CISM is frequently listed as a requirement in public sector and regulated industry tenders, which makes it a practical gate for consulting work.

$120k-$170k

Prerequisites & Requirements

  • There is no prerequisite to sit the exam. ISACA states the CISM exam is open to anyone with an interest in information security, and you may take it before meeting the experience requirement.
  • For certification, a minimum of five years of professional information security management work experience within the CISM job practice areas is required.
  • That work experience must have been gained within the 10-year period preceding the date of your certification application.
  • Experience waivers are available for the CISM to a maximum of two years, so at least three years of qualifying experience cannot be waived.
  • Certification also requires paying the US$50 application processing fee and submitting the certification application.
  • You must agree to adhere to ISACA's Code of Professional Ethics and to the Continuing Professional Education policy.
  • You have five years from your exam passing date to apply for certification; after that the passing result no longer supports an application.
  • Exam registration and full payment are required before you can schedule, and you can book a testing appointment as early as 48 hours after payment clears.

Frequently Asked Questions

What happens if I fail the CISM exam?

You get four attempts within a rolling 12-month period, and you pay the full registration fee for every attempt. The waiting periods are fixed: 30 days from the first attempt before you may sit attempt two, then 90 days after attempt two before attempt three, and 90 days after attempt three before attempt four. Your score report shows domain-level percentages, which is the only diagnostic ISACA provides since question-level results are never released.

How much does the CISM exam cost?

US$575 for ISACA members and US$760 for non-members, based on your membership status at the time of registration. Fees are nonrefundable and nontransferable. Beyond the exam there is a US$50 application processing fee to become certified, and after that an annual maintenance fee of US$45 for members or US$85 for non-members.

What is the passing score and how does the scale work?

You need 450 on a scaled range of 200 to 800. A score of 800 means every question was answered correctly and 200 is the lowest possible score. ISACA converts raw scores to this common scale so that different versions of the exam are comparable and fair. Domain-level results appear on the report for information only; the pass decision is based on the total number of items answered correctly across the whole exam.

How long do results take?

You see a preliminary pass or fail status on screen immediately after finishing the exam. The official score is emailed and posted to the MyISACA Certifications and CPE Management page within 10 working days. ISACA does not provide scores by telephone or fax, and question-level results are not released. If you passed, the notification includes instructions for applying for certification.

Can I request a rescore?

Yes, through the ISACA support page within 30 days of the release of exam results. Requests submitted after 30 days are not processed. Each request must include your name, ISACA ID number, and mailing address, and must be accompanied by a fee of US$75. Separately, comments about exam day issues or site concerns must be submitted within 48 hours of finishing the test and are reviewed before official scores are released.

What ID do I need on exam day?

One current, valid, original government-issued ID that shows your name, your signature, and your photograph, all on the same document. Acceptable forms include a driver's license, a state ID card, and a passport. Copies, handwritten IDs, and digital IDs are not accepted. Driver's licenses issued in Japan without a signature are accepted as an exception. The first and last name must match your exam registration or you may be refused entry and forfeit the fee.

What are the rules for the remotely proctored version?

Your desk and surrounding area must be completely clear of other items and materials, and you must face the screen for the entire four hours so the proctor can monitor the session. No other person may be in the room or walk through it. Screenshots and recording devices are forbidden. After the mirror check, any mobile phone must be placed out of reach of the testing room. ISACA publishes a separate Remote Proctoring Guide covering the device compatibility check and secure browser installation.

Am I allowed a calculator or any reference materials?

No. Calculators are explicitly prohibited, as are reference materials, study materials, paper, notes, notepads, and language dictionaries. Also banned are multiple monitors, mobile phones, tablets, smart watches or glasses, headphones and earbuds, bags of any kind, weapons, tobacco and vaping products, and food and beverages including water. At a testing center, personal items go in a locker and cannot be accessed until you have submitted the exam.

Can I take a break during the four hours?

Two breaks are permitted, each no longer than ten minutes, and each requires your proctor's permission. The exam is paused during an approved break but the timer does not stop, so the time comes out of your 240 minutes. Leaving the testing center or the designated remote testing area without authorization may result in your exam being terminated. If you leave to use the facilities you must check out and check back in.

How do I request special testing accommodations?

Accommodations must be requested during the exam registration process and approved by ISACA before you schedule the exam. You check the special accommodation requirement field during registration, print the Special Accommodation Request Form, and complete and submit it. Do not schedule your appointment until the request has been approved.

What are the experience requirements for certification?

A minimum of five years of professional information security management work experience within the CISM job practice areas, gained within the 10-year period preceding your application date. Experience waivers are available up to a maximum of two years, so at least three years cannot be waived. You can sit and pass the exam before meeting this requirement, and you then have five years from the passing date to submit the application with the US$50 processing fee.

How do I keep the certification once I have it?

By continuing education rather than re-examination. You must earn and report a minimum of 20 CPE hours each year and at least 120 CPE hours across each three-year reporting period, and pay the annual maintenance fee by 1 January. The fee is US$45 for ISACA members and US$85 for non-members, dropping to US$25 for members and US$50 for non-members on your third and any subsequent ISACA certification. CPE hours can count toward multiple ISACA certifications when the activity is relevant to each.

What happens if I am selected for a CPE audit?

You must provide supporting documentation for every activity reported in the specified calendar year, and failure to comply results in revocation of your CISM. Acceptable documentation includes a letter, certificate of completion, attendance roster, Verification of Attendance form, or other independent attestation, and each record must show the attendee name, sponsoring organization, activity title and description, date, and number of hours. Keep records for 12 months after the end of each three-year cycle.

How long is my exam eligibility valid, and can I extend it?

Eligibility is established when you register and lasts six months. If you do not schedule and sit the exam in that window you forfeit the fee, since fees are nonrefundable and nontransferable. A six-month extension can be purchased for US$75, and the option appears on your dashboard from 30 days before your eligibility expires until 30 days after, with a maximum of one extension per exam. Appointments are only bookable 90 days in advance, so check back closer to your target date if nothing is showing.

Can I reschedule my appointment?

Yes, at any point during your eligibility period and without penalty, provided you do it a minimum of 48 hours before the scheduled appointment. Inside 48 hours you must sit the exam or forfeit the registration fee. Changes to the exam type also require contacting ISACA support at least 48 hours ahead.

How does CISM compare to CISSP?

CISM is a four-hour, 150-question management exam covering four domains, with 63 percent of the content on running a security program and managing incidents. ISC2's CISSP covers eight domains and reaches much further into technical territory such as cryptography, secure software development, and network architecture. CISM requires five years of information security management experience specifically; CISSP requires five years across two of its eight domains. Many security leaders hold both, taking CISSP for technical breadth and CISM for the management and governance framing.

How does CISM compare to ISACA's CISA and CRISC?

All three run 240 minutes with 150 multiple-choice questions and use the same 200 to 800 scale with a 450 pass mark, and all three cost US$575 for members and US$760 for non-members. The difference is the job. CISA is for IS auditors and requires five years of IS/IT audit, control, assurance, or security experience with waivers up to three years. CRISC is for IT risk management and IS control, requiring three years with no waivers at all. CISM is for security management, requiring five years with waivers up to two.

The exam content outline changes on 3 November 2026. What does that mean for me?

ISACA has stated that the CISM exam will reflect the new Exam Content Outline from 3 November 2026, and that updated preparation material for the new outline goes on sale in September 2026. ISACA has also said that purchasing current material does not grant access to the newer material later. If your test date falls on or after that cutover, buy the new material; if it falls before, the current outline and materials apply.

50% OFF

Pass CISM (Certified Information Security Manager), Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $144
$144
$28850% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund